CVE-2020-25507
Summary
| CVE | CVE-2020-25507 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-28 20:15:00 UTC |
| Updated | 2021-01-04 19:15:00 UTC |
| Description | An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arbitrary code as root. During installation, the user is instructed to set the system enviroment file with world writable permissions (0777 /etc/environment). Any local unprivileged user can execute arbitrary code simply by writing to /etc/environment, which will force all users, including root, to execute arbitrary code during the next login or reboot. In addition, the entire home directory of the twcloud user at /home/twcloud is recursively given world writable permissions. This allows any local unprivileged attacker to execute arbitrary code, as twcloud. This product was previous named Cameo Enterprise Data Warehouse (CEDW). |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | 3ds | Teamwork Cloud | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Finding a Vulnerability in Teamwork Cloud Server (NoMagic, 3DS), Which Is Used By Gov/Enterprise to Design Rockets, Missiles, and Satellites. - Sick Codes - Linux, NetSec, VPS, Arch, Debian, CentOS Tweaks & Tips! | MISC | sick.codes | |
| Installation on Linux using scripts | MISC | docs.nomagic.com | Third Party Advisory |
| Installation on Linux (RedHat/CentOS 7.x) - Teamwork Cloud 18.5 SP2 - Documentation | MISC | web.archive.org | |
| No Magic Community Forum • View topic - Finding and fixing wrong file permission - TWC installation | CONFIRM | community.nomagic.com | |
| Wayback Machine | MISC | web.archive.org | |
| security/SICK-2020-002.md at master · sickcodes/security · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE-2020-25507 - NoMagic (Dassault Systèmes 3DS) Teamwork Cloud 18.0-19.0 - Incorrect Permissions Assignment for a Critical Resource Allows Arbitrary Code Execution and Local Privilege Escalation to Root. - Sick Codes - Linux, NetSec, VPS, Arch, Debian, CentOS Tweaks & Tips! | MISC | sick.codes | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.